Interested in being a speaker at CSAW?
Alon Hillel-Tuch
Joel Caminer
Ramesh Karri
alon.h@nyu.edu
jc5429@nyu.edu
rk1330@nyu.edu
Abstract
Hacking isn't just about code—it's a way of thinking. We understand how things really work: from bootloaders to bypasses; from side channels to sandboxes. But while we pride ourselves on breaking systems, the biggest ones shaping our world feel untouchable. They aren't. In this talk, we'll explore what I learned building a startup, and why our community has the mindset, skills, and determination to do more than play in sandboxes others have built. The world doesn't just need more hackers finding bugs: it needs us to create and shape the future, bringing our values and ethos where they're desperately needed.
Luna Tong
Luna is the CEO and co-founder of Zellic, a boutique cybersecurity research and consulting firm. Prior to founding Zellic, she was a vulnerability researcher and reverse engineer, helping found Perfect Blue, the #1-ranked CTF team in 2020, 2021, and 2023.
Abstract
While often perceived as a routine task, vulnerability management are essential in fortifying cybersecurity defenses. This talk explores how proactive vulnerability management not only identifies potential threats before attackers can exploit them but also strengthens an organization’s security posture. By regularly assessing and updating software, we create an active, ongoing shield against emerging threats. Attendees will gain insight into the latest strategies for effective vulnerability management, learn why this process is vital for resilient cybersecurity, and understand how it can serve as a powerful, proactive defense.
Gaurav Kumar Srivastava
Gaurav Srivastava is an cybersecurity consultant with a background in vulnerability management, incident handling, and industrial control systems. He holds certifications including Certified Information Security Manager (CISM) and Global Industrial Cyber Security Professional (GICSP) and has experience in areas like vulnerability management, software transparency, incident response. Gaurav earned a Master’s degree in Computer Science from Technical University of Munich, Germany and has worked with organizations such as Siemens for past 7+ years, where he served as a security consultant and research professional. His academic experience includes time as a visiting research scholar at Carnegie Mellon University, where he worked on privacy concerns in Android applications.
Abstract
This presentation conceptualizes incident response as it relates to the utility industry. Throughout the presentation, key components will be discussed such as why incident response is needed, the importance of preparing for an event, how utility incident response has some differences when compared with a formal response, and all the teams that assist in ensuring a successful outcome. The intent is to spread awareness, but to also provide some exposure to the various routes an aspiring cyber security professional could aim for when starting their career.
Michael Zelinski
Michael Zelinski is a military veteran, information technology engineer, and cyber security operations manager with a background in IT and OT systems. Mike has experience ranging from building and maintaining security tools to working in cyber incident response. Mike has worked in fast-paced, complex work environments domestically and overseas with a focus on safety, operational excellence, and a +1-customer experience. In his spare time, Mike enjoys traveling to new destinations and interactive museums/centers – think Spyscape, escape rooms, or Activate.
Kanan Vaidya
Kanan has more than 15 years of experience in information security, IT infrastructure, risk assessments, and cloud security.
· Implemented independent cybersecurity management practices across various technology, retail, and financial organizations.
· Joined TIAA in 2022 as lead cybersecurity governance and risk specialist and is responsible for leading the initiative HAGRID (hyper automated governance and risk identification platform)
· Implemented independent cybersecurity management practices across various technology, retail, and financial organizations.
· Joined TIAA in 2022 as lead cybersecurity governance and risk specialist and is responsible for leading the initiative HAGRID (hyper automated governance and risk identification platform)
Liz Vasquez
· Liz has more than 20 years of experience in information technology and cybersecurity. · Implemented application, container and cloud security continuous controls across several Financial Organizations. Ideating and Directing threat prevention and risk mitigation across hybrid enterprise cloud and container platforms and technologies
· Prior to her Cybersecurity roles, Elizabeth was an Application Architect and Software Engineer delivering an Enterprise Payment Solution
· Joined TIAA in 2023 to lead the rapid evolution and further integration of our Cybersecurity controls with our Continuous Pipelines.
· Prior to her Cybersecurity roles, Elizabeth was an Application Architect and Software Engineer delivering an Enterprise Payment Solution
· Joined TIAA in 2023 to lead the rapid evolution and further integration of our Cybersecurity controls with our Continuous Pipelines.
Dan Guido
Dan Guido is the CEO and co-founder of Trail of Bits, a cybersecurity firm that partners with high-stakes innovators to secure mission-critical technologies. Under his leadership since 2012, Trail of Bits has grown to over 100 elite engineers, with industry-defining practices in cryptography, AI, and blockchain security. The firm has been a finalist in DARPA’s Cyber Grand Challenge and AI Cyber Challenge (AIxCC), exemplifying its expertise in automated security and AI-driven defenses. Committed to building the world’s best home for security researchers, Dan has fostered a company culture recognized among NYC’s Best Places to Work. In 2023, iVerify—a tool developed to combat mobile spyware—spun out as its own company, empowering users worldwide to secure their mobile devices and their privacy.
Dan is a sought-after advisor to startups, government agencies, and policymakers on matters related to technology and cybersecurity. He serves on the boards of three startups, and he actively shapes cybersecurity policy through collaborations with leading organizations like the Council on Foreign Relations, RAND Corporation, and Harvard University. As the founder of Empire Hacking, he has connected over 1,700 NYC cybersecurity experts, and he created AlgoVPN, a popular self-hosted VPN with over 28,000 stars on GitHub.
Dan holds a bachelor’s degree in Computer Science from NYU Tandon, with a concentration in Information Assurance, and is currently enrolled in Harvard Business School’s Owner/President Management program, where he is one session in. In 2021, Dan was inducted into the prestigious Scholarship for Service (SFS) Hall of Fame by the Cybersecurity and Infrastructure Security Agency (CISA), honoring his extensive contributions to the field. A pivotal role early in his career was as Hacker in Residence at NYU, where he helped establish and grow the university's cybersecurity program, advising students and launching initiatives that connected academia with industry needs. Dan continues to leverage his expertise to inspire future generations in the cybersecurity community.
Dan is a sought-after advisor to startups, government agencies, and policymakers on matters related to technology and cybersecurity. He serves on the boards of three startups, and he actively shapes cybersecurity policy through collaborations with leading organizations like the Council on Foreign Relations, RAND Corporation, and Harvard University. As the founder of Empire Hacking, he has connected over 1,700 NYC cybersecurity experts, and he created AlgoVPN, a popular self-hosted VPN with over 28,000 stars on GitHub.
Dan holds a bachelor’s degree in Computer Science from NYU Tandon, with a concentration in Information Assurance, and is currently enrolled in Harvard Business School’s Owner/President Management program, where he is one session in. In 2021, Dan was inducted into the prestigious Scholarship for Service (SFS) Hall of Fame by the Cybersecurity and Infrastructure Security Agency (CISA), honoring his extensive contributions to the field. A pivotal role early in his career was as Hacker in Residence at NYU, where he helped establish and grow the university's cybersecurity program, advising students and launching initiatives that connected academia with industry needs. Dan continues to leverage his expertise to inspire future generations in the cybersecurity community.
Abstract
The worlds of physical security and cybersecurity are destined to combine eventually. Just as OT and IT are now coming into frame as one set of interdependent and systemic risks, the historical separation of security operations into physical and cyber aspects is also converging. This talk is a reprise of my OSAC.gov Americas & Cyber Fall 2025 Summit in Miami in September on trends in the industry with a view towards genAI (both good and bad).
Mike Wilkes
Mike has built, transformed and protected ASCAP, Marvel, ING Bank, CME Group, Sony, Macy's and many other global brands. Recognized in 2020 as a technology pioneer, he provides thought leadership on cyber resilience in the oil and gas industry as well as quantum security working groups. A featured speaker at Black Hat, Gartner, GovWare, SecureWorld and SANS, he is an adjunct professor who teaches cybersecurity and risk management at NYU and Columbia while advising several startups.
Abstract
Trail of Bits' Buttercup secured $3 million in DARPA's AI Cyber Challenge, autonomously finding 28 vulnerabilities across 20 CWE categories and patching them with high accuracy. This talk will delve into how our open-source system operates, covering AI-guided fuzzing, static analysis, and other key features. You will learn the key ideas that informed Buttercup's design and enabled its success during the competition and beyond. This talk will show how Buttercup makes world-class automated vulnerability discovery and patching accessible to everyone.
Ron Eytchison
Ron Eytchison is a Security Engineer at Trail of Bits in the Research & Engineering Practice. He was a core developer on the Trail of Bits Buttercup team and built the LLM-driven vulnerability discovery component. He is interested in applying AI to secure software. Additionally, he has worked on projects in areas spanning static analysis, fuzzing, performance benchmarking, and compilers.
Abstract
CTFs are great, but how do those skills translate into gainful employment? This talk explores how skills developed in CTFs and other hacking competitions transfer into the “real world.” We’ll chat about what the average CTF challenge looks like, what real world projects look like, and what to expect as you transition from internships to full-time careers.
Anna Staats
Anna Staats is a Security Researcher at Zetier and a former member of the UMBC Cyberdawgs. She has over seven years of experience in the security industry, specializing in embedded vulnerability research.
Raf Portnoy
Rafail Portnoy became the MTA’s Chief Technology Officer in January 2020. He is leading the transformation of the Information Technology Department, including major initiatives that will further consolidate, modernize, and standardize the MTA’s technology environment, systems and applications while enhancing cybersecurity posture. His goal is to continue building a robust, agile, and customer-focused IT department essential for supporting efficient service delivery and transformation throughout the MTA. Portnoy is currently a member of the teaching faculty at NYU Tandon School of Computer Sciences and Engineering. He holds a Master of Science degree in Information Systems Engineering from Brooklyn Polytechnic (now NYU) and a Bachelor of Business Administration degree in Management Information Systems from Pace University. He resides in Rockland County, New York, with his wife and two children.
Abstract
Hosting CTFs online is great and all, but nothing compares to the chaos, energy, and community of an onsite event. This talk makes the case for bringing more CTFs into the physical world: why YOU should host them, what makes them uniquely rewarding, and how to pull them off without melting your infrastructure or yourself in the process.
Robert Chen
Robert Chen plays with DiceGang and works at OtterSec. He’s a contributor to DiceCTF, an on-site CTF based in New York.
Michael Debono
Michael Debono plays with Friendly Maltese Citizens and hacks on security stuff at OtterSec. He's helped run several onsite CTFs, most recently MaltaCTF, and spends too much time thinking about how to encourage greater collaboration among people across different technology domains.
Abstract
This presentation explores the evolving landscape of offensive cybersecurity, focusing on the tactics of Red Team professionals and the growing impact of artificial intelligence on social engineering attacks. It contrasts traditional penetration testing with advanced Red Team operations, highlighting methodologies such as threat emulation, vulnerability assessments, and physical security exploits. Additionally highlighting how AI amplifies social engineering techniques, examines real-world case studies, and illustrates the risks posed by human and vendor vulnerabilities.
Shawn P. Baird
Accomplished cybersecurity leader with almost 30 years of deep expertise across IT, Cyber Security, and GRC with a proven track record of working across both private and public industries architecting cyber-resilient networks and security architecture, leading high-impact cybersecurity initiatives enhancing infrastructures in critical sectors both public and private. Currently leads the DTCC Offensive Cyber Security team on initiatives with DTCC involving Red/Blue/Purple Team assessments, Policy Development, and Regulatory Management.